IT Security Analyst (FedRAMPRMF)
Herndon, VA - USA
Job Summary
Contract Details
Work Mode: Hybrid (in-office TuesdayThursday; may increase to 5 days/week)
Location: Herndon VA
Schedule: 40 hours/week
Duration: 08/10/2026 08/09/2027
About the Opportunity
This role supports cloud security compliance for a government-focused environment. You will develop and maintain FedRAMP-required security documentation and artifacts drive Continuous Compliance Monitoring (CCM) manage POA&Ms and advise stakeholders on evolving regulatory and cloud security policies.
The position partners closely with Cloud Operations to identify prioritize and remediate vulnerabilities (including container security) while applying frameworks such as NIST RMF and FISMA to ensure sustained authorization and control compliance.
Key Responsibilities
- Create update and maintain FedRAMP security documentation and associated artifacts (e.g. ATO packages POA&Ms CCM evidence).
- Advise stakeholders on regulatory and cloud security policies (e.g. NIST RMF DISA SRG) and document multiple courses of action with risk/benefit tradeoffs.
- Apply enterprise security frameworks (FISMA NIST SP 800 series NIST 800-171 DFARS) to cloud environments and related initiatives.
- Develop/update policies and procedures to implement and sustain FedRAMP and NIST 800-171 compliance.
- Assist with vulnerability management using a risk-based approach to prioritize and drive remediation.
- Automate security and vulnerability analysis workflows using scripts (Python Bash PowerShell Java).
- Analyze container vulnerabilities and define remediation paths across OS and application layers; leverage container scanning tools.
- Support CI/CD security integration including AWS ECR and container image mirroring.
- Assess cloud system posture (vulnerabilities RMF package status patching/CSVA mechanisms) and interpret system/network diagrams.
- Contribute to security support across testing development staging and pre-production environments.
Required Qualifications
- US citizenship is required; dual citizenship is not permitted.
- Hybrid onsite presence in Herndon VA (TuesdayThursday) with the ability to increase to 5 days/week as needed.
- Hands-on experience producing and managing FedRAMP authorization documentation and artifacts (ATO packages POA&Ms CCM).
- Strong knowledge of NIST RMF FISMA NIST SP 800 series (including 800-171) and DFARS.
- Experience with DISA STIGs/SRGs and CNSSI.
- Vulnerability management expertise including container vulnerability assessment and remediation planning.
- Scripting/automation skills with Python Bash PowerShell and/or Java.
- Experience with container scanning tools CI/CD pipelines AWS ECR and container image mirroring.
- Solid understanding of systems and networking concepts; ability to interpret network diagrams (e.g. Visio).
- Effective presentation and public speaking skills.
- Bachelors degree in computer information systems or math/sciences.
Preferred Qualifications
- Experience with SAP products.
Work Environment
- Fast-paced team-oriented environment collaborating closely with Cloud Operations and cross-functional stakeholders.
Required Experience:
IC